Security & Threat Intelligence · 30.07.2026, 17:34 UTC
Schneider Electric IGSS
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 30.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-12927. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams for plant personnel, enabling them to monitor and control the SCADA system. Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could result in the loss of control of the system. The following versions of Schneider Electric IGSS are affected:
IGSS () IGSS Definition (Def.exe) module vers:intdot/<=18.0.0.26124, 18.0.0.26125 ()
CVSS Vendor Equipment Vulnerabilities
v3 7.8 Schneider Electric Schneider Electric IGSS Out-of-bounds Write
Background
Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: France
Vulnerabilities
Expand All +
CVE-2026-12927
An out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition. View CVE Details
Affected Products Schneider Electric IGSS
Vendor:Schneider Electric Product Version: Product Status:fixed, known_affected
Remediations Vendor fixVersion 18.0.0.26125 of the IGSS Definition module includes a fix for this vulnerability and is available for download through IGSS …